Key management system and methods for distributed software
Abstract
A key management system for distributed software applications includes a communication network and one or more software applications coupled to the communication network. The one or more software applications include an identification code that identifies each software application and a registration module that requests a key pair from a key pair provider, the key pair including a public key and a private key. The system also includes a management console coupled to at least some of the one or more software applications via the communication network and that is configured to store the public key associated with a first software application of the one or more software applications and to provide the public key associated with the first software application to a second software application of the one or more software applications upon receiving a subscription request for the first software application from the second software application.
Claims
exact text as granted — not AI-modified1 . A key management system for distributed software applications, the system comprising:
a communication network; one or more software applications coupled to the communication network, each of the one or more of software applications including an identification code that identifies each software application and a registration module that requests a key pair from a key pair provider, the key pair including a public key and a private key; a management console coupled to at least some of the one or more software applications via the communication network, the management console configured to store the public key associated with a first software application of the one or more software applications and to provide the public key associated with the first software application to a second software application of the one or more software applications upon receiving a subscription request for the first software application from the second software application.
2 . The system of claim 1 , wherein each of the one or more software applications are located on different servers.
3 . The system of claim 1 , wherein the at least two of the one or more software applications are located on a same server.
4 . The system of claim 1 , further comprising:
a central key store, coupled to the management console, that stores public keys associated with the one or more software applications.
5 . The system of claim 1 , wherein the registration modules requests the key pair from the management console and registers the key pair with the management console.
6 . The system of claim 1 , wherein the registration modules request key pairs from a third-party key pair provided external to the management console.
7 . The system of claim 1 , wherein the management console is located on a first server and at least one of the software applications is located on the first server.
8 . A method of managing key distribution in a system including distributed software applications, the method comprising:
receiving a registration request from a first software application of the distributed software applications at a key management console, the request including an identification code that identifies the first software application; storing the identification code and a public key associated with the first software application at the key management console; receiving a subscription request for the first software application from a second software application of the distributed software applications at the key management console; determining that the second software application is authorized to communicate with the first software application; and providing the public key to the second software application.
9 . The method of claim 8 , further comprising:
receiving a new public key at the key management console from the first software application; replacing the public key with the new public key; and alerting the second software application that the public key has been replaced.
10 . The method of claim 9 , further comprising:
receiving a request from the second software application for the new public key; and providing the new public key to the second software application.
11 . The method of claim 9 , wherein the public key includes an expiration time and wherein the method further comprises:
notifying the first software application that the public key has expired.
12 . The method of claim 8 , further comprising:
determining that the public key has expired; generating a new key pair at the key management console, the key pair including a new public key and a new private key; replacing the public key with the new public key in the key management console; providing the new public key to the first software application; and providing the new public key to the second software application.
13 . The method of claim 8 , further comprising:
receiving information identifying software applications that can register with the key management console, the listing including the first software application and the second software application; generating the identification code for the first software application and an identification code for the second software application; providing the identification code for the first software application to the first software application; and providing the identification code for the second software application to the second software application.
14 . The method of claim 13 , wherein determining is based on the identification code for the second software application.
15 . A method of communicating between a first software application and a second software application in a distributed software system, the method comprising:
sending, from the first software application operating a first server, a registration request to a key management console at a central server, the registration request including an identification code that identifies the first software application and either a public key associated with the first software application or a request for a public key that results in the assignment of a public key to the first software application; sending, from a second software application operating on a second server, a subscription request for the first software application to the key management console; receiving the public key at the second software application; and utilizing the public key to encrypt a message from the second software application to the first software application or to verify a signature on a message from the first software application to the second software application.
16 . The method of claim 15 , further comprising:
sending, from a third software application operating on a third server, a subscription request for the first software application to the key management console; receiving the public key at the third software application; and utilizing the public key to encrypt a message from the third software application to the first software application or to verify a signature on a message from the first software application to the third software application.
17 . The method of claim 15 , further comprising:
sending a revocation instruction from the first software application to the key management system; receiving an indication that the public key has been revoked at the second software application.
18 . The method of claim 17 , further comprising:
receiving a new public key for the first software application at the second software application; and updating a key registry of the second software application with the new public key.Join the waitlist — get patent alerts
Track US2012183144A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.